What is GDPR Compliance in Recruiting?
GDPR compliance in recruiting requires a lawful basis for processing candidate data, transparency about how it is used, defined retention limits, and working rights of access, rectification and erasure. It applies to any employer processing data of candidates in the European Union.
Last updated July 2026 · Reviewed by the TalentHive product team
Recruiting-specific obligations include telling candidates how long data is retained and why, obtaining consent to keep records for future opportunities, and honouring erasure requests within the statutory window. Article 22 also gives individuals rights concerning decisions based solely on automated processing — another reason a human must own every rejection.
These are architectural requirements, not policy statements: enforceable retention windows, a real erasure path that reaches every store including recordings, and tenant-level data isolation.
Related terms
EEOC Compliance
EEOC compliance means US hiring practices must not discriminate on race, colour, religion, sex, national origin, age, disability or genetic information. In practice it requires consistent, job-related selection criteria and documentation sufficient to defend any adverse decision.
Talent Pool
A talent pool is a maintained database of candidates who are potential future fits — silver-medallists from prior searches, sourced prospects, referrals and past applicants who consented to be retained. It shortens future searches by starting them with warm, pre-qualified candidates.
AI Voice Interview
An AI voice interview is a real-time spoken conversation between a candidate and an AI interviewer that asks role-specific competency questions, adapts with follow-ups, and produces a scored, transcribed result. It replaces the recruiter phone screen and can run for every applicant, around the clock.
See every applicant interviewed.
Post a role today and wake up to a ranked, bias-audited shortlist with full interview transcripts. Unlimited AI voice interviews on every plan.